Jump to content
Compatible Support Forums
Sign in to follow this  
news

[SECURITY] [DLA 402-1] tiff security update

Recommended Posts

Package : tiff

Version : 3.9.4-5+squeeze13

CVE ID : CVE-2015-8665 CVE-2015-8683

Debian Bug : 809021 808968

 

Two security flaws have been found and solved in libtiff, library that provides

support for handling Tag Image File Format (TIFF). These flaws concern out of

bounds reads in the TIFFRGBAImage interface, when parsing unsupported values

related to LogLUV and CIELab. CVE-2015-8665 was reported by limingxing and

CVE-2015-8683 by zzf of Alibaba.

 

For Debian 6 "Squeeze", these issues have been fixed in tiff version

3.9.4-5+squeeze13. We recommend you to upgrade your tiff packages.

 

Learn more about the Debian Long Term Support (LTS) Project and how to

apply these updates at: https://wiki.debian.org/LTS/

 

 

Share this post


Link to post

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now
Sign in to follow this  

×